Hive was a ransomware-as-a-service (RaaS) operation first observed in June 2021 and dismantled in January 2023 through a joint law-enforcement action. It operated an affiliate model in which core operators provided ransomware tooling, leak-site infrastructure, and negotiation support, while affiliates conducted intrusions and shared ransom proceeds. Hive is widely characterized as a double-extortion actor: affiliates stole data prior to encryption and threatened publication on the group’s leak site if victims refused to pay. The operation was notable for its high tempo, broad victimology, and repeated targeting of healthcare organizations despite the potential for operational harm. Hive targeted enterprises across multiple sectors, including healthcare, manufacturing, legal, energy, finance, technology, and government-related organizations. Victims were observed in North America, Europe, and Latin America, with especially frequent reporting involving the United States and Canada. Healthcare intrusions were a defining feature of the group’s activity, including disruptive attacks on hospitals and health-plan providers. Initial access and intrusion tradecraft associated with Hive included phishing with malicious attachments, exploitation of vulnerable Microsoft Exchange servers via ProxyShell, abuse of exposed RDP, use of compromised VPN credentials, and socially engineered access paths linked to callback-phishing ecosystems. Post-compromise activity included deployment of Cobalt Strike, credential theft with tools such as Mimikatz and LSASS dumping, Active Directory reconnaissance with utilities such as ADFind, SharpView, BloodHound, and ADRecon, password spraying, lateral movement via RDP, WMI, scheduled tasks, and Group Policy, and data exfiltration prior to encryption. Hive operators and affiliates also showed strong defense-evasion behavior, including disabling security tools, deleting shadow copies, clearing logs, terminating backup and database processes, and using obfuscated loaders to stage payloads. Hive malware was initially associated with Windows payloads written in Go and later expanded to Linux, FreeBSD, and VMware ESXi-targeting variants. Reporting also indicates the developers later ported code to Rust. The malware supported command-line execution and was used in human-operated intrusions rather than indiscriminate mass deployment. Hive affiliates were observed using publicly available penetration-testing frameworks and custom loaders, including an obfuscation method known as IPfuscation that encoded shellcode as address-like strings before reconstructing and executing a Cobalt Strike stager at runtime. The group maintained leak-site infrastructure and centralized victim negotiations, and affiliates could generate ransomware builds rapidly through the operator-managed platform. Some reporting indicated that Hive’s decryptor was unreliable and in some cases damaged virtualized systems. In January 2023, Hive’s infrastructure was seized and the operation ceased. Subsequent reporting noted code overlap and possible asset transfer involving Hunters International, although Hive and Hunters International should be treated as distinct entities.
Mallory correlates actor tradecraft and target patterns against your stack, your sector, and your geography. See overlap before they land.
Who, where, and (when attributed) which flag flies behind the operation. Pulled from open-source reporting and Mallory's analyst review.
Sectors the actor has been observed targeting.
Geographies tied to known operations.
51 distinct techniques observed across reporting, grouped by tactic. Hover any cell for the evidence excerpt; click through for MITRE's full description.
3 CVEs this actor has used in observed campaigns. 3 of them exploited in the wild.
CVE-2021-31207 (Base Score: 7.2) Microsoft Exchange Server Security Feature Bypass Vulnerability... During the investigation, we found specific exploitation evidence of these CVEs... which allowed the adversary to deploy webshells successfully on the compromised server.
CVE-2021-34473 (Base Score: 9.8) Microsoft Exchange Server Remote Code Execution Vulnerability... During the investigation, we found specific exploitation evidence of these CVEs... which allowed the adversary to deploy webshells successfully on the compromised server. | First, the attacker exploited multiple Exchange security vulnerabilities, referred to as ProxyShell... ProxyShell involves a set of three separate security flaws and allows remote attackers to execute arbitrary code on affected installations of Microsoft Exchange Server.
CVE-2021-34523 (Base Score: 9.8) Microsoft Exchange Server Elevation of Privilege Vulnerability... During the investigation, we found specific exploitation evidence of these CVEs... which allowed the adversary to deploy webshells successfully on the compromised server.
124 indicators attributed to this actor: domains, IPs, hashes, and other artifacts pulled from reporting. View more in app.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Mentioned as a competing ransomware group that relied on access brokers.
Named as one of multiple ransomware groups operating data leak sites and listing fresh victims.
Mentioned only as another ransomware operator using Rust.
Referenced as an earlier ransomware lineage connected to Hunters International and indirectly to WorldLeaks.
Match sector + geo + tech-stack targeting against your real footprint.
Every observed MITRE ATT&CK technique, grouped by tactic.
Families this actor is known to deploy, with IOCs and behavior.
CVEs this actor has used in known campaigns.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Domains, IPs, and hashes tied to this actor, refreshed continuously.